From 2ef989163a635f7c14350f2e36882dd9a26aa8ce Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 21:32:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6mxw-q763-w6p8.json | 4 +- .../GHSA-rf8x-xcjr-27mf.json | 4 +- .../GHSA-25rm-3r9j-mwmf.json | 4 +- .../GHSA-2gx6-qrpp-c4p3.json | 37 ++++++++++++ .../GHSA-2p25-rmjx-pfqv.json | 11 +++- .../GHSA-34jr-r2pr-95hh.json | 4 +- .../GHSA-3cq2-fh6p-8w28.json | 11 +++- .../GHSA-3vv9-rrp8-6jqf.json | 15 +++-- .../GHSA-49pw-2xfg-hw49.json | 15 +++-- .../GHSA-4qmh-7fxc-x74p.json | 4 +- .../GHSA-59cm-59x5-cwhh.json | 4 +- .../GHSA-5m9p-9w9f-5c87.json | 4 +- .../GHSA-678m-q2m4-g7rf.json | 6 +- .../GHSA-6gqq-xj74-45f9.json | 15 +++-- .../GHSA-6hr7-2c35-r8xm.json | 15 +++-- .../GHSA-6wff-g5m3-3vrq.json | 37 ++++++++++++ .../GHSA-7q22-x757-cmgc.json | 37 ++++++++++++ .../GHSA-87xg-hm48-6q4p.json | 4 +- .../GHSA-8cpm-86gf-2992.json | 4 +- .../GHSA-8p49-gjw4-jcmp.json | 11 +++- .../GHSA-8ppf-9667-6mfj.json | 4 +- .../GHSA-8w2c-9h69-q63q.json | 4 +- .../GHSA-98xj-43wv-fx2j.json | 11 +++- .../GHSA-99p7-c89v-ph5p.json | 4 +- .../GHSA-9fq4-227m-74p5.json | 11 +++- .../GHSA-9fr3-g426-jq79.json | 37 ++++++++++++ .../GHSA-9r36-4w79-3hrf.json | 4 +- .../GHSA-c9hj-p989-pvmr.json | 15 ++--- .../GHSA-cg28-v4wq-whv5.json | 37 ++++++++++++ .../GHSA-cqqg-qhcp-9mqr.json | 15 +++-- .../GHSA-crqc-m66h-cvr4.json | 37 ++++++++++++ .../GHSA-ffvq-pv3x-2xfv.json | 4 +- .../GHSA-fqhc-grp9-76ch.json | 4 +- .../GHSA-gpf9-rcg2-w95g.json | 56 +++++++++++++++++++ .../GHSA-gq96-59xw-28wj.json | 37 ++++++++++++ .../GHSA-hcgq-c6f2-4jh5.json | 15 +++-- .../GHSA-j4r5-m4h2-m93g.json | 33 +++++++++++ .../GHSA-m7vh-7qm6-rq42.json | 15 +++-- .../GHSA-prhx-whmf-2rx6.json | 4 +- .../GHSA-pw36-wp35-2rw6.json | 37 ++++++++++++ .../GHSA-qqrf-32q3-9249.json | 15 +++-- .../GHSA-r2xg-c3rj-xj8r.json | 4 +- .../GHSA-r5f8-46f5-h4jg.json | 4 +- .../GHSA-rhx4-chf7-v77c.json | 33 +++++++++++ .../GHSA-rj48-23jv-5ph5.json | 4 +- .../GHSA-rjgc-mwc5-8g7j.json | 11 +++- .../GHSA-v259-7c7m-x3q9.json | 4 +- .../GHSA-v43r-53w7-7crq.json | 15 +++-- .../GHSA-v456-9683-gpmq.json | 37 ++++++++++++ .../GHSA-v787-c3f2-p88r.json | 15 +++-- .../GHSA-vc5q-m359-46xj.json | 4 +- .../GHSA-vcg2-wj7m-5j2m.json | 4 +- .../GHSA-vq3g-vjx5-h9p5.json | 4 +- .../GHSA-vw34-j5vp-r98r.json | 11 +++- .../GHSA-w5f2-gvhw-r7q6.json | 33 +++++++++++ .../GHSA-w9mq-3f7x-p532.json | 11 +++- .../GHSA-wr4f-chxr-9pr5.json | 11 +++- .../GHSA-xjm8-v6p6-5c3j.json | 33 +++++++++++ 58 files changed, 736 insertions(+), 147 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7q22-x757-cmgc/GHSA-7q22-x757-cmgc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gpf9-rcg2-w95g/GHSA-gpf9-rcg2-w95g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json diff --git a/advisories/unreviewed/2024/03/GHSA-6mxw-q763-w6p8/GHSA-6mxw-q763-w6p8.json b/advisories/unreviewed/2024/03/GHSA-6mxw-q763-w6p8/GHSA-6mxw-q763-w6p8.json index 553443e0044..a97154b6bca 100644 --- a/advisories/unreviewed/2024/03/GHSA-6mxw-q763-w6p8/GHSA-6mxw-q763-w6p8.json +++ b/advisories/unreviewed/2024/03/GHSA-6mxw-q763-w6p8/GHSA-6mxw-q763-w6p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rf8x-xcjr-27mf/GHSA-rf8x-xcjr-27mf.json b/advisories/unreviewed/2024/03/GHSA-rf8x-xcjr-27mf/GHSA-rf8x-xcjr-27mf.json index 7a9e0350c72..8a313a0b1f9 100644 --- a/advisories/unreviewed/2024/03/GHSA-rf8x-xcjr-27mf/GHSA-rf8x-xcjr-27mf.json +++ b/advisories/unreviewed/2024/03/GHSA-rf8x-xcjr-27mf/GHSA-rf8x-xcjr-27mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-25rm-3r9j-mwmf/GHSA-25rm-3r9j-mwmf.json b/advisories/unreviewed/2024/11/GHSA-25rm-3r9j-mwmf/GHSA-25rm-3r9j-mwmf.json index 39b99e4963c..a256c1282c6 100644 --- a/advisories/unreviewed/2024/11/GHSA-25rm-3r9j-mwmf/GHSA-25rm-3r9j-mwmf.json +++ b/advisories/unreviewed/2024/11/GHSA-25rm-3r9j-mwmf/GHSA-25rm-3r9j-mwmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json b/advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json new file mode 100644 index 00000000000..5d757873409 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gx6-qrpp-c4p3", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-35371" + ], + "details": "Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35371" + }, + { + "type": "WEB", + "url": "https://github.com/ant-media/ant-media-server/commit/4d4763bd4fd06e515c19544e5170ca0f34c9ce45" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/4eb17867f2e375f4824274c5e7b4d384" + }, + { + "type": "WEB", + "url": "https://github.com/ant-media/Ant-Media-Server/blob/ams-v2.8.2/src/main/java/io/antmedia/rest/RestServiceBase.java#L356" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2p25-rmjx-pfqv/GHSA-2p25-rmjx-pfqv.json b/advisories/unreviewed/2024/11/GHSA-2p25-rmjx-pfqv/GHSA-2p25-rmjx-pfqv.json index a1fc45d51f2..a3e02b05fc0 100644 --- a/advisories/unreviewed/2024/11/GHSA-2p25-rmjx-pfqv/GHSA-2p25-rmjx-pfqv.json +++ b/advisories/unreviewed/2024/11/GHSA-2p25-rmjx-pfqv/GHSA-2p25-rmjx-pfqv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2p25-rmjx-pfqv", - "modified": "2024-11-08T06:30:48Z", + "modified": "2024-11-29T21:31:01Z", "published": "2024-11-08T06:30:48Z", "aliases": [ "CVE-2024-50181" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: imx: Remove CLK_SET_PARENT_GATE for DRAM mux for i.MX7D\n\nFor i.MX7D DRAM related mux clock, the clock source change should ONLY\nbe done done in low level asm code without accessing DRAM, and then\ncalling clk API to sync the HW clock status with clk tree, it should never\ntouch real clock source switch via clk API, so CLK_SET_PARENT_GATE flag\nshould NOT be added, otherwise, DRAM's clock parent will be disabled when\nDRAM is active, and system will hang.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-34jr-r2pr-95hh/GHSA-34jr-r2pr-95hh.json b/advisories/unreviewed/2024/11/GHSA-34jr-r2pr-95hh/GHSA-34jr-r2pr-95hh.json index dd29476d5a3..a1f8fe3b82e 100644 --- a/advisories/unreviewed/2024/11/GHSA-34jr-r2pr-95hh/GHSA-34jr-r2pr-95hh.json +++ b/advisories/unreviewed/2024/11/GHSA-34jr-r2pr-95hh/GHSA-34jr-r2pr-95hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-3cq2-fh6p-8w28/GHSA-3cq2-fh6p-8w28.json b/advisories/unreviewed/2024/11/GHSA-3cq2-fh6p-8w28/GHSA-3cq2-fh6p-8w28.json index a4d70a10534..8f8365a5e5c 100644 --- a/advisories/unreviewed/2024/11/GHSA-3cq2-fh6p-8w28/GHSA-3cq2-fh6p-8w28.json +++ b/advisories/unreviewed/2024/11/GHSA-3cq2-fh6p-8w28/GHSA-3cq2-fh6p-8w28.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3cq2-fh6p-8w28", - "modified": "2024-11-28T06:32:42Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-28T06:32:42Z", "aliases": [ "CVE-2024-38389" ], "details": "There is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-28T03:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3vv9-rrp8-6jqf/GHSA-3vv9-rrp8-6jqf.json b/advisories/unreviewed/2024/11/GHSA-3vv9-rrp8-6jqf/GHSA-3vv9-rrp8-6jqf.json index 225bea21ec3..ed5a44f2630 100644 --- a/advisories/unreviewed/2024/11/GHSA-3vv9-rrp8-6jqf/GHSA-3vv9-rrp8-6jqf.json +++ b/advisories/unreviewed/2024/11/GHSA-3vv9-rrp8-6jqf/GHSA-3vv9-rrp8-6jqf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vv9-rrp8-6jqf", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-29T21:31:02Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50196" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: ocelot: fix system hang on level based interrupts\n\nThe current implementation only calls chained_irq_enter() and\nchained_irq_exit() if it detects pending interrupts.\n\n```\nfor (i = 0; i < info->stride; i++) {\n\turegmap_read(info->map, id_reg + 4 * i, ®);\n\tif (!reg)\n\t\tcontinue;\n\n\tchained_irq_enter(parent_chip, desc);\n```\n\nHowever, in case of GPIO pin configured in level mode and the parent\ncontroller configured in edge mode, GPIO interrupt might be lowered by the\nhardware. In the result, if the interrupt is short enough, the parent\ninterrupt is still pending while the GPIO interrupt is cleared;\nchained_irq_enter() never gets called and the system hangs trying to\nservice the parent interrupt.\n\nMoving chained_irq_enter() and chained_irq_exit() outside the for loop\nensures that they are called even when GPIO interrupt is lowered by the\nhardware.\n\nThe similar code with chained_irq_enter() / chained_irq_exit() functions\nwrapping interrupt checking loop may be found in many other drivers:\n```\ngrep -r -A 10 chained_irq_enter drivers/pinctrl\n```", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-49pw-2xfg-hw49/GHSA-49pw-2xfg-hw49.json b/advisories/unreviewed/2024/11/GHSA-49pw-2xfg-hw49/GHSA-49pw-2xfg-hw49.json index b67fd0eb79a..09982728091 100644 --- a/advisories/unreviewed/2024/11/GHSA-49pw-2xfg-hw49/GHSA-49pw-2xfg-hw49.json +++ b/advisories/unreviewed/2024/11/GHSA-49pw-2xfg-hw49/GHSA-49pw-2xfg-hw49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-49pw-2xfg-hw49", - "modified": "2024-11-29T18:34:03Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-29T18:34:03Z", "aliases": [ "CVE-2024-36624" ], "details": "Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T18:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4qmh-7fxc-x74p/GHSA-4qmh-7fxc-x74p.json b/advisories/unreviewed/2024/11/GHSA-4qmh-7fxc-x74p/GHSA-4qmh-7fxc-x74p.json index 73fbcb61f2a..d4db4ab61a0 100644 --- a/advisories/unreviewed/2024/11/GHSA-4qmh-7fxc-x74p/GHSA-4qmh-7fxc-x74p.json +++ b/advisories/unreviewed/2024/11/GHSA-4qmh-7fxc-x74p/GHSA-4qmh-7fxc-x74p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-59cm-59x5-cwhh/GHSA-59cm-59x5-cwhh.json b/advisories/unreviewed/2024/11/GHSA-59cm-59x5-cwhh/GHSA-59cm-59x5-cwhh.json index 146daf9a84e..ba0ce4ec43c 100644 --- a/advisories/unreviewed/2024/11/GHSA-59cm-59x5-cwhh/GHSA-59cm-59x5-cwhh.json +++ b/advisories/unreviewed/2024/11/GHSA-59cm-59x5-cwhh/GHSA-59cm-59x5-cwhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-5m9p-9w9f-5c87/GHSA-5m9p-9w9f-5c87.json b/advisories/unreviewed/2024/11/GHSA-5m9p-9w9f-5c87/GHSA-5m9p-9w9f-5c87.json index 9867c47601f..856685b9854 100644 --- a/advisories/unreviewed/2024/11/GHSA-5m9p-9w9f-5c87/GHSA-5m9p-9w9f-5c87.json +++ b/advisories/unreviewed/2024/11/GHSA-5m9p-9w9f-5c87/GHSA-5m9p-9w9f-5c87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-678m-q2m4-g7rf/GHSA-678m-q2m4-g7rf.json b/advisories/unreviewed/2024/11/GHSA-678m-q2m4-g7rf/GHSA-678m-q2m4-g7rf.json index f96279b2dea..a1449566bb4 100644 --- a/advisories/unreviewed/2024/11/GHSA-678m-q2m4-g7rf/GHSA-678m-q2m4-g7rf.json +++ b/advisories/unreviewed/2024/11/GHSA-678m-q2m4-g7rf/GHSA-678m-q2m4-g7rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-678m-q2m4-g7rf", - "modified": "2024-11-20T09:32:54Z", + "modified": "2024-11-29T21:31:02Z", "published": "2024-11-20T09:32:54Z", "aliases": [ "CVE-2024-10900" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json b/advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json index 950bfab9502..9f70b58c492 100644 --- a/advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json +++ b/advisories/unreviewed/2024/11/GHSA-6gqq-xj74-45f9/GHSA-6gqq-xj74-45f9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6gqq-xj74-45f9", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-29T06:35:29Z", "aliases": [ "CVE-2024-54123" ], "details": "Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T04:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6hr7-2c35-r8xm/GHSA-6hr7-2c35-r8xm.json b/advisories/unreviewed/2024/11/GHSA-6hr7-2c35-r8xm/GHSA-6hr7-2c35-r8xm.json index a80382644cf..c27fd64fb93 100644 --- a/advisories/unreviewed/2024/11/GHSA-6hr7-2c35-r8xm/GHSA-6hr7-2c35-r8xm.json +++ b/advisories/unreviewed/2024/11/GHSA-6hr7-2c35-r8xm/GHSA-6hr7-2c35-r8xm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hr7-2c35-r8xm", - "modified": "2024-11-08T18:30:49Z", + "modified": "2024-11-29T21:31:01Z", "published": "2024-11-08T06:30:48Z", "aliases": [ "CVE-2024-50180" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: sisfb: Fix strbuf array overflow\n\nThe values of the variables xres and yres are placed in strbuf.\nThese variables are obtained from strbuf1.\nThe strbuf1 array contains digit characters\nand a space if the array contains non-digit characters.\nThen, when executing sprintf(strbuf, \"%ux%ux8\", xres, yres);\nmore than 16 bytes will be written to strbuf.\nIt is suggested to increase the size of the strbuf array to 24.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json b/advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json new file mode 100644 index 00000000000..6cdaa8b2145 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wff-g5m3-3vrq", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-35367" + ], + "details": "FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35367" + }, + { + "type": "WEB", + "url": "https://github.com/ffmpeg/ffmpeg/commit/09e6840cf7a3ee07a73c3ae88a020bf27ca1a667" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/9754a44845578358f6a403447c458ca4" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavcodec/ppc/vp8dsp_altivec.c#L53" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7q22-x757-cmgc/GHSA-7q22-x757-cmgc.json b/advisories/unreviewed/2024/11/GHSA-7q22-x757-cmgc/GHSA-7q22-x757-cmgc.json new file mode 100644 index 00000000000..a981bba65e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7q22-x757-cmgc/GHSA-7q22-x757-cmgc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q22-x757-cmgc", + "modified": "2024-11-29T21:31:03Z", + "published": "2024-11-29T21:31:03Z", + "aliases": [ + "CVE-2024-36611" + ], + "details": "In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36611" + }, + { + "type": "WEB", + "url": "https://github.com/symfony/symfony/commit/a804ca15fcad279d7727b91d12a667fd5b925995" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/3581425e0911b716cf8ce4fa30e41e6c" + }, + { + "type": "WEB", + "url": "https://github.com/symfony/symfony/blob/v7.0.7/src/Symfony/Component/Security/Http/Authenticator/FormLoginAuthenticator.php#L132" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-87xg-hm48-6q4p/GHSA-87xg-hm48-6q4p.json b/advisories/unreviewed/2024/11/GHSA-87xg-hm48-6q4p/GHSA-87xg-hm48-6q4p.json index 65ab4518934..421f3203603 100644 --- a/advisories/unreviewed/2024/11/GHSA-87xg-hm48-6q4p/GHSA-87xg-hm48-6q4p.json +++ b/advisories/unreviewed/2024/11/GHSA-87xg-hm48-6q4p/GHSA-87xg-hm48-6q4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8cpm-86gf-2992/GHSA-8cpm-86gf-2992.json b/advisories/unreviewed/2024/11/GHSA-8cpm-86gf-2992/GHSA-8cpm-86gf-2992.json index 86a320a4d4b..085627e13c8 100644 --- a/advisories/unreviewed/2024/11/GHSA-8cpm-86gf-2992/GHSA-8cpm-86gf-2992.json +++ b/advisories/unreviewed/2024/11/GHSA-8cpm-86gf-2992/GHSA-8cpm-86gf-2992.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8p49-gjw4-jcmp/GHSA-8p49-gjw4-jcmp.json b/advisories/unreviewed/2024/11/GHSA-8p49-gjw4-jcmp/GHSA-8p49-gjw4-jcmp.json index d2df6f3d2c9..87a8496e4fb 100644 --- a/advisories/unreviewed/2024/11/GHSA-8p49-gjw4-jcmp/GHSA-8p49-gjw4-jcmp.json +++ b/advisories/unreviewed/2024/11/GHSA-8p49-gjw4-jcmp/GHSA-8p49-gjw4-jcmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8p49-gjw4-jcmp", - "modified": "2024-11-08T18:30:49Z", + "modified": "2024-11-29T21:31:01Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50194" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: probes: Fix uprobes for big-endian kernels\n\nThe arm64 uprobes code is broken for big-endian kernels as it doesn't\nconvert the in-memory instruction encoding (which is always\nlittle-endian) into the kernel's native endianness before analyzing and\nsimulating instructions. This may result in a few distinct problems:\n\n* The kernel may may erroneously reject probing an instruction which can\n safely be probed.\n\n* The kernel may erroneously erroneously permit stepping an\n instruction out-of-line when that instruction cannot be stepped\n out-of-line safely.\n\n* The kernel may erroneously simulate instruction incorrectly dur to\n interpretting the byte-swapped encoding.\n\nThe endianness mismatch isn't caught by the compiler or sparse because:\n\n* The arch_uprobe::{insn,ixol} fields are encoded as arrays of u8, so\n the compiler and sparse have no idea these contain a little-endian\n 32-bit value. The core uprobes code populates these with a memcpy()\n which similarly does not handle endianness.\n\n* While the uprobe_opcode_t type is an alias for __le32, both\n arch_uprobe_analyze_insn() and arch_uprobe_skip_sstep() cast from u8[]\n to the similarly-named probe_opcode_t, which is an alias for u32.\n Hence there is no endianness conversion warning.\n\nFix this by changing the arch_uprobe::{insn,ixol} fields to __le32 and\nadding the appropriate __le32_to_cpu() conversions prior to consuming\nthe instruction encoding. The core uprobes copies these fields as opaque\nranges of bytes, and so is unaffected by this change.\n\nAt the same time, remove MAX_UINSN_BYTES and consistently use\nAARCH64_INSN_SIZE for clarity.\n\nTested with the following:\n\n| #include \n| #include \n|\n| #define noinline __attribute__((noinline))\n|\n| static noinline void *adrp_self(void)\n| {\n| void *addr;\n|\n| asm volatile(\n| \" adrp %x0, adrp_self\\n\"\n| \" add %x0, %x0, :lo12:adrp_self\\n\"\n| : \"=r\" (addr));\n| }\n|\n|\n| int main(int argc, char *argv)\n| {\n| void *ptr = adrp_self();\n| bool equal = (ptr == adrp_self);\n|\n| printf(\"adrp_self => %p\\n\"\n| \"adrp_self() => %p\\n\"\n| \"%s\\n\",\n| adrp_self, ptr, equal ? \"EQUAL\" : \"NOT EQUAL\");\n|\n| return 0;\n| }\n\n.... where the adrp_self() function was compiled to:\n\n| 00000000004007e0 :\n| 4007e0: 90000000 adrp x0, 400000 <__ehdr_start>\n| 4007e4: 911f8000 add x0, x0, #0x7e0\n| 4007e8: d65f03c0 ret\n\nBefore this patch, the ADRP is not recognized, and is assumed to be\nsteppable, resulting in corruption of the result:\n\n| # ./adrp-self\n| adrp_self => 0x4007e0\n| adrp_self() => 0x4007e0\n| EQUAL\n| # echo 'p /root/adrp-self:0x007e0' > /sys/kernel/tracing/uprobe_events\n| # echo 1 > /sys/kernel/tracing/events/uprobes/enable\n| # ./adrp-self\n| adrp_self => 0x4007e0\n| adrp_self() => 0xffffffffff7e0\n| NOT EQUAL\n\nAfter this patch, the ADRP is correctly recognized and simulated:\n\n| # ./adrp-self\n| adrp_self => 0x4007e0\n| adrp_self() => 0x4007e0\n| EQUAL\n| #\n| # echo 'p /root/adrp-self:0x007e0' > /sys/kernel/tracing/uprobe_events\n| # echo 1 > /sys/kernel/tracing/events/uprobes/enable\n| # ./adrp-self\n| adrp_self => 0x4007e0\n| adrp_self() => 0x4007e0\n| EQUAL", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8ppf-9667-6mfj/GHSA-8ppf-9667-6mfj.json b/advisories/unreviewed/2024/11/GHSA-8ppf-9667-6mfj/GHSA-8ppf-9667-6mfj.json index fbc17c2df76..137ff14e338 100644 --- a/advisories/unreviewed/2024/11/GHSA-8ppf-9667-6mfj/GHSA-8ppf-9667-6mfj.json +++ b/advisories/unreviewed/2024/11/GHSA-8ppf-9667-6mfj/GHSA-8ppf-9667-6mfj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8w2c-9h69-q63q/GHSA-8w2c-9h69-q63q.json b/advisories/unreviewed/2024/11/GHSA-8w2c-9h69-q63q/GHSA-8w2c-9h69-q63q.json index f6ae9faaf08..f89945c8520 100644 --- a/advisories/unreviewed/2024/11/GHSA-8w2c-9h69-q63q/GHSA-8w2c-9h69-q63q.json +++ b/advisories/unreviewed/2024/11/GHSA-8w2c-9h69-q63q/GHSA-8w2c-9h69-q63q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-98xj-43wv-fx2j/GHSA-98xj-43wv-fx2j.json b/advisories/unreviewed/2024/11/GHSA-98xj-43wv-fx2j/GHSA-98xj-43wv-fx2j.json index 294b93a5188..965641dfd70 100644 --- a/advisories/unreviewed/2024/11/GHSA-98xj-43wv-fx2j/GHSA-98xj-43wv-fx2j.json +++ b/advisories/unreviewed/2024/11/GHSA-98xj-43wv-fx2j/GHSA-98xj-43wv-fx2j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98xj-43wv-fx2j", - "modified": "2024-11-08T18:30:49Z", + "modified": "2024-11-29T21:31:01Z", "published": "2024-11-08T06:30:48Z", "aliases": [ "CVE-2024-50179" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: remove the incorrect Fw reference check when dirtying pages\n\nWhen doing the direct-io reads it will also try to mark pages dirty,\nbut for the read path it won't hold the Fw caps and there is case\nwill it get the Fw reference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -53,7 +58,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json b/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json index b5301b831ee..90aec8ed6ce 100644 --- a/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json +++ b/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-9fq4-227m-74p5/GHSA-9fq4-227m-74p5.json b/advisories/unreviewed/2024/11/GHSA-9fq4-227m-74p5/GHSA-9fq4-227m-74p5.json index ab8adb5cec0..26736ac28b7 100644 --- a/advisories/unreviewed/2024/11/GHSA-9fq4-227m-74p5/GHSA-9fq4-227m-74p5.json +++ b/advisories/unreviewed/2024/11/GHSA-9fq4-227m-74p5/GHSA-9fq4-227m-74p5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9fq4-227m-74p5", - "modified": "2024-11-08T06:30:48Z", + "modified": "2024-11-29T21:31:01Z", "published": "2024-11-08T06:30:48Z", "aliases": [ "CVE-2024-50182" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsecretmem: disable memfd_secret() if arch cannot set direct map\n\nReturn -ENOSYS from memfd_secret() syscall if !can_set_direct_map(). This\nis the case for example on some arm64 configurations, where marking 4k\nPTEs in the direct map not present can only be done if the direct map is\nset up at 4k granularity in the first place (as ARM's break-before-make\nsemantics do not easily allow breaking apart large/gigantic pages).\n\nMore precisely, on arm64 systems with !can_set_direct_map(),\nset_direct_map_invalid_noflush() is a no-op, however it returns success\n(0) instead of an error. This means that memfd_secret will seemingly\n\"work\" (e.g. syscall succeeds, you can mmap the fd and fault in pages),\nbut it does not actually achieve its goal of removing its memory from the\ndirect map.\n\nNote that with this patch, memfd_secret() will start erroring on systems\nwhere can_set_direct_map() returns false (arm64 with\nCONFIG_RODATA_FULL_DEFAULT_ENABLED=n, CONFIG_DEBUG_PAGEALLOC=n and\nCONFIG_KFENCE=n), but that still seems better than the current silent\nfailure. Since CONFIG_RODATA_FULL_DEFAULT_ENABLED defaults to 'y', most\narm64 systems actually have a working memfd_secret() and aren't be\naffected.\n\nFrom going through the iterations of the original memfd_secret patch\nseries, it seems that disabling the syscall in these scenarios was the\nintended behavior [1] (preferred over having\nset_direct_map_invalid_noflush return an error as that would result in\nSIGBUSes at page-fault time), however the check for it got dropped between\nv16 [2] and v17 [3], when secretmem moved away from CMA allocations.\n\n[1]: https://lore.kernel.org/lkml/20201124164930.GK8537@kernel.org/\n[2]: https://lore.kernel.org/lkml/20210121122723.3446-11-rppt@kernel.org/#t\n[3]: https://lore.kernel.org/lkml/20201125092208.12544-10-rppt@kernel.org/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json b/advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json new file mode 100644 index 00000000000..9df67bcbe93 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fr3-g426-jq79", + "modified": "2024-11-29T21:31:03Z", + "published": "2024-11-29T21:31:03Z", + "aliases": [ + "CVE-2024-36615" + ], + "details": "FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36615" + }, + { + "type": "WEB", + "url": "https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c#L1738" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9r36-4w79-3hrf/GHSA-9r36-4w79-3hrf.json b/advisories/unreviewed/2024/11/GHSA-9r36-4w79-3hrf/GHSA-9r36-4w79-3hrf.json index 191b67b0ced..cf2ae416d2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-9r36-4w79-3hrf/GHSA-9r36-4w79-3hrf.json +++ b/advisories/unreviewed/2024/11/GHSA-9r36-4w79-3hrf/GHSA-9r36-4w79-3hrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json b/advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json index 47afd45c3c2..c3517052a5e 100644 --- a/advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json +++ b/advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-c9hj-p989-pvmr", - "modified": "2024-11-19T21:31:33Z", + "modified": "2024-11-29T21:31:02Z", "published": "2024-11-19T21:31:33Z", "aliases": [ "CVE-2024-52763" ], "details": "A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the \"g\" parameter.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -25,9 +26,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json b/advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json new file mode 100644 index 00000000000..e930abe8bb5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg28-v4wq-whv5", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-36610" + ], + "details": "A deserialization vulnerability exists in the Stub class of the VarDumper module in Symfony v7.0.3. The vulnerability stems from deficiencies in the original implementation when handling properties with null or uninitialized values. An attacker could construct specific serialized data and use this vulnerability to execute unauthorized code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36610" + }, + { + "type": "WEB", + "url": "https://github.com/symfony/symfony/commit/3ffd495bb3cc4d2e24e35b2d83c5b909cab7e259" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/24e93f2905850235e42ad7db6e878bd5" + }, + { + "type": "WEB", + "url": "https://github.com/symfony/symfony/blob/v7.0.3/src/Symfony/Component/VarDumper/Cloner/Stub.php#L53" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json b/advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json index f620bf37940..4e2bb5cc925 100644 --- a/advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json +++ b/advisories/unreviewed/2024/11/GHSA-cqqg-qhcp-9mqr/GHSA-cqqg-qhcp-9mqr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqqg-qhcp-9mqr", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-29T06:35:29Z", "aliases": [ "CVE-2024-54124" ], "details": "In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json b/advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json new file mode 100644 index 00000000000..ac678248195 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crqc-m66h-cvr4", + "modified": "2024-11-29T21:31:03Z", + "published": "2024-11-29T21:31:03Z", + "aliases": [ + "CVE-2024-36616" + ], + "details": "An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36616" + }, + { + "type": "WEB", + "url": "https://github.com/ffmpeg/ffmpeg/commit/86f73277bf014e2ce36dd2594f1e0fb8b3bd6661" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/ded3e1509d8296ec4a91817867d108e0" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/westwood_vqa.c#L265" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ffvq-pv3x-2xfv/GHSA-ffvq-pv3x-2xfv.json b/advisories/unreviewed/2024/11/GHSA-ffvq-pv3x-2xfv/GHSA-ffvq-pv3x-2xfv.json index ebe603d4ba2..66d8305b152 100644 --- a/advisories/unreviewed/2024/11/GHSA-ffvq-pv3x-2xfv/GHSA-ffvq-pv3x-2xfv.json +++ b/advisories/unreviewed/2024/11/GHSA-ffvq-pv3x-2xfv/GHSA-ffvq-pv3x-2xfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-fqhc-grp9-76ch/GHSA-fqhc-grp9-76ch.json b/advisories/unreviewed/2024/11/GHSA-fqhc-grp9-76ch/GHSA-fqhc-grp9-76ch.json index b6337d46068..7e3f707d653 100644 --- a/advisories/unreviewed/2024/11/GHSA-fqhc-grp9-76ch/GHSA-fqhc-grp9-76ch.json +++ b/advisories/unreviewed/2024/11/GHSA-fqhc-grp9-76ch/GHSA-fqhc-grp9-76ch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-gpf9-rcg2-w95g/GHSA-gpf9-rcg2-w95g.json b/advisories/unreviewed/2024/11/GHSA-gpf9-rcg2-w95g/GHSA-gpf9-rcg2-w95g.json new file mode 100644 index 00000000000..a4654c5b252 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gpf9-rcg2-w95g/GHSA-gpf9-rcg2-w95g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpf9-rcg2-w95g", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-11995" + ], + "details": "A vulnerability has been found in code-projects Farmacia 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /pagamento.php. The manipulation of the argument total leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11995" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/5p4rk/cve/blob/main/xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286411" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286411" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.453639" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json b/advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json new file mode 100644 index 00000000000..46bc2e3217a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq96-59xw-28wj", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-35366" + ], + "details": "FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35366" + }, + { + "type": "WEB", + "url": "https://github.com/ffmpeg/ffmpeg/commit/0bed22d597b78999151e3bde0768b7fe763fc2a6" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/1e72f170d58c2547ebd4db4cdf6cfabf" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/sbgdec.c#L389" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hcgq-c6f2-4jh5/GHSA-hcgq-c6f2-4jh5.json b/advisories/unreviewed/2024/11/GHSA-hcgq-c6f2-4jh5/GHSA-hcgq-c6f2-4jh5.json index 9448e5f2fe8..c2d5f467cf0 100644 --- a/advisories/unreviewed/2024/11/GHSA-hcgq-c6f2-4jh5/GHSA-hcgq-c6f2-4jh5.json +++ b/advisories/unreviewed/2024/11/GHSA-hcgq-c6f2-4jh5/GHSA-hcgq-c6f2-4jh5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hcgq-c6f2-4jh5", - "modified": "2024-11-27T18:34:04Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-27T18:34:04Z", "aliases": [ "CVE-2024-51228" ], "details": "An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T17:15:12Z" diff --git a/advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json b/advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json new file mode 100644 index 00000000000..ef9b7252db4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4r5-m4h2-m93g", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-53507" + ], + "details": "A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53507" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13057" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13077" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m7vh-7qm6-rq42/GHSA-m7vh-7qm6-rq42.json b/advisories/unreviewed/2024/11/GHSA-m7vh-7qm6-rq42/GHSA-m7vh-7qm6-rq42.json index add1a5ba0fc..3a5a6f2e72d 100644 --- a/advisories/unreviewed/2024/11/GHSA-m7vh-7qm6-rq42/GHSA-m7vh-7qm6-rq42.json +++ b/advisories/unreviewed/2024/11/GHSA-m7vh-7qm6-rq42/GHSA-m7vh-7qm6-rq42.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m7vh-7qm6-rq42", - "modified": "2024-11-27T18:34:04Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-27T18:34:04Z", "aliases": [ "CVE-2024-31976" ], "details": "EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T17:15:10Z" diff --git a/advisories/unreviewed/2024/11/GHSA-prhx-whmf-2rx6/GHSA-prhx-whmf-2rx6.json b/advisories/unreviewed/2024/11/GHSA-prhx-whmf-2rx6/GHSA-prhx-whmf-2rx6.json index ffd67ccb66c..b376916d018 100644 --- a/advisories/unreviewed/2024/11/GHSA-prhx-whmf-2rx6/GHSA-prhx-whmf-2rx6.json +++ b/advisories/unreviewed/2024/11/GHSA-prhx-whmf-2rx6/GHSA-prhx-whmf-2rx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json b/advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json new file mode 100644 index 00000000000..f9ced6c0689 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw36-wp35-2rw6", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-35368" + ], + "details": "FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35368" + }, + { + "type": "WEB", + "url": "https://github.com/ffmpeg/ffmpeg/commit/4513300989502090c4fd6560544dce399a8cd53c" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/7e6e47220ae2b2d2fb4611f0d8a31ec5" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/rkmppdec.c#L466" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qqrf-32q3-9249/GHSA-qqrf-32q3-9249.json b/advisories/unreviewed/2024/11/GHSA-qqrf-32q3-9249/GHSA-qqrf-32q3-9249.json index 2112d9d27ea..2896cbe0826 100644 --- a/advisories/unreviewed/2024/11/GHSA-qqrf-32q3-9249/GHSA-qqrf-32q3-9249.json +++ b/advisories/unreviewed/2024/11/GHSA-qqrf-32q3-9249/GHSA-qqrf-32q3-9249.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqrf-32q3-9249", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-29T21:31:02Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50198" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: veml6030: fix IIO device retrieval from embedded device\n\nThe dev pointer that is received as an argument in the\nin_illuminance_period_available_show function references the device\nembedded in the IIO device, not in the i2c client.\n\ndev_to_iio_dev() must be used to accessthe right data. The current\nimplementation leads to a segmentation fault on every attempt to read\nthe attribute because indio_dev gets a NULL assignment.\n\nThis bug has been present since the first appearance of the driver,\napparently since the last version (V6) before getting applied. A\nconstant attribute was used until then, and the last modifications might\nhave not been tested again.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r2xg-c3rj-xj8r/GHSA-r2xg-c3rj-xj8r.json b/advisories/unreviewed/2024/11/GHSA-r2xg-c3rj-xj8r/GHSA-r2xg-c3rj-xj8r.json index 986cc4f2532..b43ea913b29 100644 --- a/advisories/unreviewed/2024/11/GHSA-r2xg-c3rj-xj8r/GHSA-r2xg-c3rj-xj8r.json +++ b/advisories/unreviewed/2024/11/GHSA-r2xg-c3rj-xj8r/GHSA-r2xg-c3rj-xj8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-r5f8-46f5-h4jg/GHSA-r5f8-46f5-h4jg.json b/advisories/unreviewed/2024/11/GHSA-r5f8-46f5-h4jg/GHSA-r5f8-46f5-h4jg.json index 530ffdb9500..ac9206361e3 100644 --- a/advisories/unreviewed/2024/11/GHSA-r5f8-46f5-h4jg/GHSA-r5f8-46f5-h4jg.json +++ b/advisories/unreviewed/2024/11/GHSA-r5f8-46f5-h4jg/GHSA-r5f8-46f5-h4jg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json b/advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json new file mode 100644 index 00000000000..c63c3d2252d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhx4-chf7-v77c", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-53504" + ], + "details": "A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53504" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13058" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13077" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rj48-23jv-5ph5/GHSA-rj48-23jv-5ph5.json b/advisories/unreviewed/2024/11/GHSA-rj48-23jv-5ph5/GHSA-rj48-23jv-5ph5.json index 85abe26b82f..1c7770a3066 100644 --- a/advisories/unreviewed/2024/11/GHSA-rj48-23jv-5ph5/GHSA-rj48-23jv-5ph5.json +++ b/advisories/unreviewed/2024/11/GHSA-rj48-23jv-5ph5/GHSA-rj48-23jv-5ph5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rjgc-mwc5-8g7j/GHSA-rjgc-mwc5-8g7j.json b/advisories/unreviewed/2024/11/GHSA-rjgc-mwc5-8g7j/GHSA-rjgc-mwc5-8g7j.json index 80c4f051471..40657b2567e 100644 --- a/advisories/unreviewed/2024/11/GHSA-rjgc-mwc5-8g7j/GHSA-rjgc-mwc5-8g7j.json +++ b/advisories/unreviewed/2024/11/GHSA-rjgc-mwc5-8g7j/GHSA-rjgc-mwc5-8g7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rjgc-mwc5-8g7j", - "modified": "2024-11-28T06:32:42Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-28T06:32:42Z", "aliases": [ "CVE-2024-38658" ], "details": "There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-28T03:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v259-7c7m-x3q9/GHSA-v259-7c7m-x3q9.json b/advisories/unreviewed/2024/11/GHSA-v259-7c7m-x3q9/GHSA-v259-7c7m-x3q9.json index 4afc6a568e6..5d5cf24cebd 100644 --- a/advisories/unreviewed/2024/11/GHSA-v259-7c7m-x3q9/GHSA-v259-7c7m-x3q9.json +++ b/advisories/unreviewed/2024/11/GHSA-v259-7c7m-x3q9/GHSA-v259-7c7m-x3q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-v43r-53w7-7crq/GHSA-v43r-53w7-7crq.json b/advisories/unreviewed/2024/11/GHSA-v43r-53w7-7crq/GHSA-v43r-53w7-7crq.json index 02be1026f7f..50c74be166e 100644 --- a/advisories/unreviewed/2024/11/GHSA-v43r-53w7-7crq/GHSA-v43r-53w7-7crq.json +++ b/advisories/unreviewed/2024/11/GHSA-v43r-53w7-7crq/GHSA-v43r-53w7-7crq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v43r-53w7-7crq", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-29T21:31:02Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50197" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: intel: platform: fix error path in device_for_each_child_node()\n\nThe device_for_each_child_node() loop requires calls to\nfwnode_handle_put() upon early returns to decrement the refcount of\nthe child node and avoid leaking memory if that error path is triggered.\n\nThere is one early returns within that loop in\nintel_platform_pinctrl_prepare_community(), but fwnode_handle_put() is\nmissing.\n\nInstead of adding the missing call, the scoped version of the loop can\nbe used to simplify the code and avoid mistakes in the future if new\nearly returns are added, as the child node is only used for parsing, and\nit is never assigned.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json b/advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json new file mode 100644 index 00000000000..133ebda15c4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v456-9683-gpmq", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-36612" + ], + "details": "Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36612" + }, + { + "type": "WEB", + "url": "https://github.com/zulip/zulip/commit/0a90a13becbf0338a8fc1ad37946e51c2c25b0a5" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/f7ff51d24ebbb29e21dfb70a0c97302b" + }, + { + "type": "WEB", + "url": "https://github.com/zulip/zulip/blob/8.3/web/src/click_handlers.js" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v787-c3f2-p88r/GHSA-v787-c3f2-p88r.json b/advisories/unreviewed/2024/11/GHSA-v787-c3f2-p88r/GHSA-v787-c3f2-p88r.json index 8384ac8bad9..67b826c9cf9 100644 --- a/advisories/unreviewed/2024/11/GHSA-v787-c3f2-p88r/GHSA-v787-c3f2-p88r.json +++ b/advisories/unreviewed/2024/11/GHSA-v787-c3f2-p88r/GHSA-v787-c3f2-p88r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v787-c3f2-p88r", - "modified": "2024-11-08T18:30:50Z", + "modified": "2024-11-29T21:31:02Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50195" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-clock: Fix missing timespec64 check in pc_clock_settime()\n\nAs Andrew pointed out, it will make sense that the PTP core\nchecked timespec64 struct's tv_sec and tv_nsec range before calling\nptp->info->settime64().\n\nAs the man manual of clock_settime() said, if tp.tv_sec is negative or\ntp.tv_nsec is outside the range [0..999,999,999], it should return EINVAL,\nwhich include dynamic clocks which handles PTP clock, and the condition is\nconsistent with timespec64_valid(). As Thomas suggested, timespec64_valid()\nonly check the timespec is valid, but not ensure that the time is\nin a valid range, so check it ahead using timespec64_valid_strict()\nin pc_clock_settime() and return -EINVAL if not valid.\n\nThere are some drivers that use tp->tv_sec and tp->tv_nsec directly to\nwrite registers without validity checks and assume that the higher layer\nhas checked it, which is dangerous and will benefit from this, such as\nhclge_ptp_settime(), igb_ptp_settime_i210(), _rcar_gen4_ptp_settime(),\nand some drivers can remove the checks of itself.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vc5q-m359-46xj/GHSA-vc5q-m359-46xj.json b/advisories/unreviewed/2024/11/GHSA-vc5q-m359-46xj/GHSA-vc5q-m359-46xj.json index 534eef54f83..ad98d56e2f7 100644 --- a/advisories/unreviewed/2024/11/GHSA-vc5q-m359-46xj/GHSA-vc5q-m359-46xj.json +++ b/advisories/unreviewed/2024/11/GHSA-vc5q-m359-46xj/GHSA-vc5q-m359-46xj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-vcg2-wj7m-5j2m/GHSA-vcg2-wj7m-5j2m.json b/advisories/unreviewed/2024/11/GHSA-vcg2-wj7m-5j2m/GHSA-vcg2-wj7m-5j2m.json index 9fd120bbdff..e667a6526e4 100644 --- a/advisories/unreviewed/2024/11/GHSA-vcg2-wj7m-5j2m/GHSA-vcg2-wj7m-5j2m.json +++ b/advisories/unreviewed/2024/11/GHSA-vcg2-wj7m-5j2m/GHSA-vcg2-wj7m-5j2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-vq3g-vjx5-h9p5/GHSA-vq3g-vjx5-h9p5.json b/advisories/unreviewed/2024/11/GHSA-vq3g-vjx5-h9p5/GHSA-vq3g-vjx5-h9p5.json index 7e4cfe4e2ca..50a7b3c1ad0 100644 --- a/advisories/unreviewed/2024/11/GHSA-vq3g-vjx5-h9p5/GHSA-vq3g-vjx5-h9p5.json +++ b/advisories/unreviewed/2024/11/GHSA-vq3g-vjx5-h9p5/GHSA-vq3g-vjx5-h9p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-vw34-j5vp-r98r/GHSA-vw34-j5vp-r98r.json b/advisories/unreviewed/2024/11/GHSA-vw34-j5vp-r98r/GHSA-vw34-j5vp-r98r.json index f361b4dfb81..0a367b577ea 100644 --- a/advisories/unreviewed/2024/11/GHSA-vw34-j5vp-r98r/GHSA-vw34-j5vp-r98r.json +++ b/advisories/unreviewed/2024/11/GHSA-vw34-j5vp-r98r/GHSA-vw34-j5vp-r98r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vw34-j5vp-r98r", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-29T21:31:01Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50193" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/entry_32: Clear CPU buffers after register restore in NMI return\n\nCPU buffers are currently cleared after call to exc_nmi, but before\nregister state is restored. This may be okay for MDS mitigation but not for\nRDFS. Because RDFS mitigation requires CPU buffers to be cleared when\nregisters don't have any sensitive data.\n\nMove CLEAR_CPU_BUFFERS after RESTORE_ALL_NMI.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json b/advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json new file mode 100644 index 00000000000..583adb54e82 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5f2-gvhw-r7q6", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-53506" + ], + "details": "A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53506" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13060" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13077" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w9mq-3f7x-p532/GHSA-w9mq-3f7x-p532.json b/advisories/unreviewed/2024/11/GHSA-w9mq-3f7x-p532/GHSA-w9mq-3f7x-p532.json index a268c7936b8..5d2b243c798 100644 --- a/advisories/unreviewed/2024/11/GHSA-w9mq-3f7x-p532/GHSA-w9mq-3f7x-p532.json +++ b/advisories/unreviewed/2024/11/GHSA-w9mq-3f7x-p532/GHSA-w9mq-3f7x-p532.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w9mq-3f7x-p532", - "modified": "2024-11-28T06:32:41Z", + "modified": "2024-11-29T21:31:03Z", "published": "2024-11-28T06:32:41Z", "aliases": [ "CVE-2024-38309" ], "details": "There are multiple stack-based buffer overflow vulnerabilities in V-SFT (v6.2.2.0 and earlier), TELLUS (v4.0.19.0 and earlier), and TELLUS Lite (v4.0.19.0 and earlier).\nIf a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-28T03:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wr4f-chxr-9pr5/GHSA-wr4f-chxr-9pr5.json b/advisories/unreviewed/2024/11/GHSA-wr4f-chxr-9pr5/GHSA-wr4f-chxr-9pr5.json index 56b1fc6fff4..ff5a00a06d5 100644 --- a/advisories/unreviewed/2024/11/GHSA-wr4f-chxr-9pr5/GHSA-wr4f-chxr-9pr5.json +++ b/advisories/unreviewed/2024/11/GHSA-wr4f-chxr-9pr5/GHSA-wr4f-chxr-9pr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr4f-chxr-9pr5", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-29T21:31:01Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50192" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/gic-v4: Don't allow a VMOVP on a dying VPE\n\nKunkun Jiang reported that there is a small window of opportunity for\nuserspace to force a change of affinity for a VPE while the VPE has already\nbeen unmapped, but the corresponding doorbell interrupt still visible in\n/proc/irq/.\n\nPlug the race by checking the value of vmapp_count, which tracks whether\nthe VPE is mapped ot not, and returning an error in this case.\n\nThis involves making vmapp_count common to both GICv4.1 and its v4.0\nancestor.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json b/advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json new file mode 100644 index 00000000000..e743c21e936 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjm8-v6p6-5c3j", + "modified": "2024-11-29T21:31:04Z", + "published": "2024-11-29T21:31:04Z", + "aliases": [ + "CVE-2024-53505" + ], + "details": "A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53505" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13059" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/issues/13077" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T20:15:20Z" + } +} \ No newline at end of file